Regulatory alignment, mapped to Firevault.
We map Firevault OSS and Control to the frameworks that matter most: NIS2, DORA, UK GDPR, ISO 27001, PCI DSS, CAF, FCA, Cyber Essentials Plus, NHS DSPT and the SRA. Alignment, not a certification claim.
- NIS2
- DORA
- UK GDPR
- ISO 27001
- NCSC CAF

11
Frameworks mapped to Firevault
OSS & Control coverage
24h
NIS2 significant-incident window
EU Directive 2022/2555
72h
UK GDPR breach notification window
ICO / Article 33
CAF-aligned
Controls mapped to NCSC outcomes
Alignment, not certification
Alignment, evidenced. Not certification, claimed.
Regulators do not ask for a badge. They ask for demonstrable technical and organisational measures, proportionate to the risk. Offline Secure Storage® takes data offline. Control governs the path used to reach systems and data. Both produce evidence a regulator or auditor can read.
Where we say CAF-aligned, we mean controls mapped to NCSC CAF outcomes. Where we say Article 32 supporting, we mean measures a controller can point to. We do not issue certifications and do not accept audit outcomes on your behalf.
The three that drive most conversations.
NIS2, DORA and UK GDPR set the tone for how regulators expect crown-jewel data and critical services to be protected.
NIS2
Network & Information Security Directive 2
Risk-based security measures, 24-hour significant-incident reporting and supply-chain assurance for essential and important entities.
How Firevault helps: OSS supports business continuity and offline gold copies. Control governs the path used to reach essential systems and provides evidence for incident timelines.
DORA
Digital Operational Resilience Act
ICT risk management, resilience testing, third-party monitoring and threat-intelligence sharing across the financial sector.
How Firevault helps: OSS holds recoverable copies away from live ICT. Control provides time-bound, evidenced access windows for third parties and privileged users.
UK GDPR
General Data Protection Regulation
Article 25 privacy-by-design, Article 32 appropriate technical measures and 72-hour breach notification for personal data.
How Firevault helps: Offline storage supports appropriate technical measures under Article 32. Identity-locked, time-boxed access supports proportionality and accountability.
Standards, sector rules and certifications.
ISO 27001, NCSC CAF, PCI DSS, FCA operational resilience, Cyber Essentials Plus, NHS DSPT and SRA. Mapped, not marketed.
Framework matrixISO 27001
Information Security Management Systems
Annex A controls covering asset management, access control, cryptography and operations security across the ISMS.
How Firevault helps: OSS contributes to A.8 asset protection and A.10 cryptography evidence. Control supports A.9 access control with time-bound windows and full audit trails.
NCSC CAF 4.0
Cyber Assessment Framework
Four objectives: managing security risk, protecting against attack, detecting events and minimising the impact of incidents.
How Firevault helps: We map Firevault controls to CAF outcomes rather than claim certification. Control supports Objective B; OSS supports Objective D recoverability.
PCI DSS 4.0
Payment Card Industry Data Security Standard
Cardholder-data protection, cryptography, access on a need-to-know basis and continuous security monitoring.
How Firevault helps: OSS holds account-data copies off the cardholder data environment. Control enforces least-privilege, session-bound access paths.
FCA Op Res
FCA PS21/3 Operational Resilience
Identify important business services, set impact tolerances and evidence resilience under severe-but-plausible scenarios.
How Firevault helps: OSS gives recoverable copies outside the live estate. Control demonstrates the ability to sever and re-lock paths during a scenario test.
Cyber Essentials Plus
UK Government-backed certification
Boundary firewalls, secure configuration, access control, malware protection and patch management, verified hands-on.
How Firevault helps: Firevault deployments run on dedicated, hardened hardware with identity-locked access and time-boxed connectivity.
NHS DSPT
Data Security & Protection Toolkit
Ten National Data Guardian standards covering confidentiality, integrity, availability and third-party assurance.
How Firevault helps: OSS supports Standard 7 confidentiality and integrity for patient records held offline. Control supports Standard 9 IT protection.
SRA Standards
Solicitors Regulation Authority
Client confidentiality, information security, third-party assurance and incident response for regulated law firms.
How Firevault helps: Deep coverage on the Legal page: matter files, disclosure bundles and privileged records under evidence-grade custody.
Two lines. Different evidence.
Most compliance programmes use both: OSS for recoverable copies and confidentiality, Control for path governance and access windows.
Offline Secure Storage®
Recoverable copies held offline. Supports Article 32 measures, NIS2 continuity, ISO 27001 A.8/A.10 and DORA recovery.
Explore OfflineControl
Path governance for IT and OT. Supports NIS2 supply chain, CAF Objective B, PCI DSS need-to-know and FCA impact tolerances.
Explore Control


Map Firevault to your regulator's language.
Send us the frameworks that apply to your organisation. We will map OSS and Control controls to the specific outcomes your auditor is testing against.
Takes about 2 minutes. No account needed.